No more typing reviews! Try our Samantha, our new voice AI agent.

RSA Archer vs Tenable Lumin comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

RSA Archer
Ranking in IT Vendor Risk Management
4th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Governance (1st)
Tenable Lumin
Ranking in IT Vendor Risk Management
20th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2026, in the IT Vendor Risk Management category, the mindshare of RSA Archer is 6.9%, down from 11.5% compared to the previous year. The mindshare of Tenable Lumin is 1.8%, up from 1.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management Mindshare Distribution
ProductMindshare (%)
RSA Archer6.9%
Tenable Lumin1.8%
Other91.3%
IT Vendor Risk Management
 

Featured Reviews

CJ
Information Security Specialist at Dubai Health Authority
Centralized management strengthens compliance with good look and feel
From my perspective as a customer and end user, Archer has an impressive look and feel, but the most adaptive feature is its ease of configuration which helps to enhance our process according to our maturity. It's more about our organization getting centralized with an integrated approach that focuses on risk governance and compliance. When can provide a detailed dashboards to management with the details of risks from top-down or bottom-up prioritizing actions based on its criticality or necessity. This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
Yusuf-Hashmi - PeerSpot reviewer
Sr. Director - Group Head - IT Security (CISO) at Jubilant Organosys Ltd., India, Leading Chemical M
It creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks
Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"With this tool, once it was built and designed, we were able to use our own internal resources, we don't need to go outside, all of the questions are already there, the policies and procedures are already built-in and you just need to tweak them a bit, so it helps us just in understanding what's there on the ground and overall it saves us a lot of money to be spent if we are taking care of these services individually."
"The solution has helped our organization manage our internal and external activities."
"RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."
"First of all, we have gained time back that was previously wasted in management meetings."
"It is enterprise-wide accessible, so it is very helpful for all the employees in our bank, with inbuilt modules for issue management, risk identification, risk assessment, and policy exception management, plus intuitive workflows and a self-explanatory user interface that can be customized to meet our requirements."
"Its ROI is quite high when you look at how long it takes for people to input stuff for compliance risk, vulnerability management, and threat management."
"With RSA Archer, an admin can set permissions for a normal user to go directly to the tool they need to input some data. Admins can then go through that and approve some requests. Also, they can log in based on these kinds of permissions, including ticketing, service patches, or upgrades."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"Tenable Lumin is very good because it helps organizations look for solutions and profit. It also helps organizations save time because it displays market data well."
"The stability of this solution is appropriate; you can sleep well at night, if you have this solution implemented in your environment."
"Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are."
"Tenable Lumin is very good because it helps organizations look for solutions and profit, and it also helps organizations save time because it displays market data well."
"The stability of this solution is appropriate. You can sleep well at night, if you have this solution implemented in your environment."
 

Cons

"I would like to have the ability to build and maintain an inventory of personal data processing activities and assets utilizing a purpose-built taxonomy and data structure."
"There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons."
"There should be an in-built feature that allows live data from vulnerabilities and threats from reliable sources to be streamed directly through their data field."
"The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky."
"A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client."
"RSA Archer might be a bit expensive for small companies because it's a vast tool."
"We've noticed recently with the advanced workflow jobs that we're receiving some errors. It's a showstopper for us and it's clear that some kind of development support is needed."
"While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard."
"Tenable Lumin isn't that old and still needs some time to mature."
"The price could be better."
"The solution's cloud operation has issues Lumin and Tenable are not one product. The integration needs to be worked out better. There is space for improvement there."
"The solution's cloud operation has issues Lumin and Tenable are not one product."
"The price could be better."
 

Pricing and Cost Advice

"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"Fairly highly-priced, especially for smaller companies."
"At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
"I am not sure about other companies, but it's quite expensive."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"The price could be better."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
885,837 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Insurance Company
11%
Manufacturing Company
7%
Government
5%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
No data available
 

Questions from the Community

What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
What advice do you have for others considering RSA Archer?
I have been in touch with about three companies who use RSA Archer actively in the compliance area. These companies use RSA Archer for nearly all purposes, including governance, internal risk, and ...
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

Archer
Lumin
 

Overview

 

Sample Customers

T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Information Not Available
Find out what your peers are saying about RSA Archer vs. Tenable Lumin and other solutions. Updated: March 2026.
885,837 professionals have used our research since 2012.